PDPL review season: impact assessment records and the DPO role

Photo: Campaign Creators / Unsplash
A law taking effect does not mean compliance is finished — that is when the review begins. From 1 January 2026, the Personal Data Protection Law (Law 91/2025/QH15) and Decree 356/2025/ND-CP, which guides it, both apply. After the first wave of writing policies and standing up processes, many organisations move on to something different in nature: checking whether what they built is correct, complete, and provable.
This piece is about that review season. It focuses on the three workstreams most often left unfinished: the data protection impact assessment records, the assessment for cross-border transfers, and the role of the data protection unit or officer. If you have not laid the groundwork yet, start with the PDPL compliance checklist first; this article is the re-check step that follows a rollout.
What a PDPL review season means
A review is not a rebuild. It is a comparison of current practice against your obligations, a search for the gaps, and a patch applied in order of priority. Four reasons make this a recurring exercise rather than a one-off.
- Operations change faster than records. A new feature, a new vendor, a marketing campaign that collects more data — each can drift a record away from reality. A review pulls the records back into line with what the systems actually do.
- Obligations are proven by documents, not by words. When an inspection arrives, what gets examined is the processing inventory, the impact assessment records, the appointment decisions, the consent logs, and the access logs. If they do not exist or have gone stale, compliance in practice carries no evidentiary weight.
- Finding gaps early is cheaper than handling them late. A data flow leaving the country unnoticed becomes a legal risk the moment it is questioned. Catching it in an internal review is always lighter than explaining it after an incident.
- Roles and responsibilities drift. The person assigned as the data protection point of contact may have changed jobs; the unit may have been reorganised. A review is the moment to re-confirm the right person with the right authority.
The cleanest way to run one is to fix a scope, assign an owner to each workstream, and set a completion date. Do not try to review everything at once; take the highest-risk workstream first, and the highest risk usually sits in the flow of data out of the country.
The impact assessment record: what is in it, when it is required
The data protection impact assessment (commonly abbreviated DPIA) is the document describing what data you process, for what purpose, on what legal basis, who can access it, how long it is kept, and the risks together with their mitigations. Its components and template are set out in Article 19 of Decree 356/2025; updating it follows Article 20.
When reviewing this workstream, examine four points.
- Whether the records cover the real activities. An organisation usually runs several processing flows at once: HR, customers, after-sales care, accounting. The review is the moment to reconcile the processing inventory against the records already prepared, and to catch any flow that arose later but was never added.
- Whether the content matches current operations. A record describes a process, but once the process changes the record must change too. This is where records tend to freeze at their first version.
- Whether the update schedule is kept. Under the rules, a record must be updated when there is a material change, such as a new processing purpose or a change in the parties involved. The review checks that an update reminder exists and is being followed.
- Whether the record is ready to present. A record that cannot be retrieved might as well not exist. It needs a central store, with versions and review dates.
A note on size: small businesses and startups have a grace period (roughly five years from the Law's effective date) for certain obligations, including the impact assessment record. This is a time-limited grace, not a permanent exemption, and it does not apply to some cases such as processing sensitive data or processing the data of a large number of subjects. The details are covered in the PDPL compliance checklist.
The assessment for cross-border transfers
This is the largest workstream by financial risk, so a review usually puts it first. The obligation to assess the impact of transferring personal data abroad (commonly the TIA) is set out in Article 18 of Decree 356/2025.
The easily-missed point is that "transfer abroad" is defined broadly: not just sending a data file out, but also using a platform or infrastructure located outside Vietnam to process data collected in Vietnam. That means a customer-care system, an email marketing tool, or an analytics service running on foreign servers may already have triggered the obligation without the organisation noticing.
So the core of reviewing this workstream is rebuilding the map of outbound data flows.
- List every system and third-party service that processes personal data, marking which run domestically and which use infrastructure outside the territory.
- For each outbound flow, identify whose data is being transferred, of what kind, to which party, and whether a corresponding impact assessment record exists.
- Consider narrowing the scope. Every system brought back onto domestic infrastructure is one record you do not have to file and one risk cluster you do not have to manage. This is one reason many organisations keep sensitive data on infrastructure they control.
Reviewing cross-border transfers is not a paperwork exercise. It forces an organisation to see exactly where its data sits — and the answer is often different from what everyone assumed.
The DPO role: when it is required, when it is exempt
The data protection unit or officer (DPO) is the point of accountability for compliance inside the organisation. Reviewing this workstream means answering three questions.
- Whether the organisation must appoint one. In principle, the duty to appoint data protection personnel applies to organisations that process personal data. Decree 356/2025 (Article 41) sets out certain exemptions or size-based relief — for household businesses, micro-enterprises, and the grace period for small businesses and startups. That relief does not apply to some cases, however, such as providing data-processing services, processing sensitive data, or processing the data of a large number of subjects. If you are unsure which regime you fall under, compare the text directly and consult legal counsel.
- Whether the appointed person is correct and adequately qualified. The appointment should be made in a formal written decision that states the functions, duties and powers, and the appointee should meet the qualification requirements. The review checks that the appointment decision is still in force, the appointee is still in place, and they have the authority to act.
- What to do if there is no one. When an organisation lacks internal resources, the rules allow it to engage an outside organisation or individual providing data protection services. That is a valid path, provided the division of responsibility is clearly recorded.
The operational duties that come with this role — from preparing records and delivering data-subject rights to reporting breaches — are recapped in Decree 356 and operational duties.
A point that is often summarised wrong: the 72-hour mark
In many write-ups, the number 72 hours is mistaken for the deadline to answer a data subject's request. It is not. The 72-hour mark is the deadline to notify the authority of a personal data breach in the specified cases, counted from discovery — not the deadline to handle a subject's request to view, correct, delete or withdraw consent.
Data-subject requests (DSARs) have their own set of deadlines, counted in days and varying by request type, detailed in the PDPL compliance checklist. The review is the moment to separate these two sets of deadlines in your internal process, so that when something real happens no one applies the wrong clock.
How to organise a review
A review runs smoothly with four things: a clear scope, an owner for each workstream, evidence left behind, and a completion date. A suggested sequence:
- Fix the scope. List the systems and processing activities to review, prioritising the highest-risk workstream (usually the outbound data flow).
- Assign owners. Each workstream gets an owner: legal for records and legal basis, IT for infrastructure and logs, the data protection officer to consolidate.
- Compare and record gaps. For each item, note the current state, the obligation, the gap, and the action needed.
- Patch in priority order. Close the gaps with the largest legal or financial risk first.
- Keep evidence. Every task leaves a provable trace: versioned records, signed decisions, timestamped logs.
When data sits on infrastructure you control, the evidence is far easier to produce: role-based permissions, access logs, and the ability to delete data are all clear. Tetra eOffice and Manta Security run on-premise, keep data in your own systems, and support exactly those pieces of evidence.
A quick review checklist
- Impact assessment records. Cover the real processing activities, match current operations, have an update schedule, and are ready to present (Articles 19–20, Decree 356).
- Outbound data flows. A map of every system and third-party service using infrastructure outside the territory; each flow has a corresponding impact assessment (Article 18, Decree 356).
- DPO role. Established whether the organisation must appoint one; the appointment decision is in force, the right person, with adequate authority; an outsourcing option if resources are short (Article 41, Decree 356).
- Deadlines. Separated the breach-notification mark (72 hours, from discovery) from the deadlines for answering data-subject requests (counted in days, by request type).
- Size. Reconciled the company size and the disqualifying cases to know which obligations apply now and which sit in the grace period.
- Evidence. Each workstream leaves provable documentation, versioned and dated, stored where it can be found.
A proactive review does not create new work so much as record and re-check what the organisation already does, in a way that can be proven. If an inspection arrives three months from now, you simply open those things. To review your current state and build a roadmap, book a consultation.
Note: this article is for reference only and is not a substitute for legal advice; organisations should check the current legal texts and consult a legal specialist.
Related articles

Transferring personal data abroad under the PDPL: records, process and penalties
The 2026 PDPL sets strict obligations for transferring personal data abroad, with the highest penalty of up to 5% of revenue. When it applies, what to file, and how to reduce risk with on-premise.
Read ↗
Deploying eOffice on-premise: data sovereignty seen from the architecture
Data sovereignty is more than servers located in Vietnam. A look at the architecture, infrastructure, integration and staffing behind an on-premise eOffice.
Read ↗
A PDPL & cybersecurity penalty decree is coming: compliance gets urgent
The Ministry of Public Security is consulting on a draft decree on administrative penalties for cybersecurity and personal data violations. PDPL gets teeth.
Read ↗Personal Data Protection checklist
Review your business before the law takes effect on 01/01/2026.